Privacy Policy
How NEXUS collects, uses, and protects personal data across the platform and this website.
Who we are
NEXUS Cloud Pte. Ltd. is a company incorporated under the laws of Singapore and operates the NEXUS advertising platform. For questions about this policy or about data we hold, contact [email protected].
This policy covers two distinct contexts: personal data processed through the NEXUS platform in the course of delivering advertising, and personal data collected when you visit this website or contact us. Where the two differ, we say so.
Data we process through the platform
Programmatic advertising relies on data transmitted in bid requests and bid responses. Depending on the publisher, the channel, and the consent signals present, this can include:
- Online identifiers, including cookie IDs, mobile advertising IDs, and identity solutions such as UID2 and ID5.
- IP address, which may be truncated or hashed depending on jurisdiction and consent state.
- Device and browser characteristics, including operating system, device type, and user agent.
- Approximate geographic location derived from IP address or supplied by the publisher.
- Contextual signals about the page, app, or stream where an impression is available.
- Ad interaction events, including impressions, clicks, and conversions reported back to the platform.
We do not seek to collect special category data, and we do not build audience segments on the basis of protected characteristics. See our Advertising Policy for the targeting restrictions we enforce.
Data we collect on this website
- Information you submit directly, such as your name, work email, company, and role when you request access or contact us.
- Usage data about how you navigate this website, collected through cookies and similar technologies described in our Cookie Policy.
Why we process it
We process personal data to operate the platform: matching advertising to available inventory, enforcing frequency and budget controls, detecting fraud and invalid traffic, measuring and reporting on delivery, and improving the models that power bid optimization and audience prediction. We also process data to respond to enquiries, to meet legal and regulatory obligations, and to establish or defend legal claims.
Legal bases
Where the GDPR applies, we rely on consent for the placement of non-essential cookies and for advertising activities requiring it; on legitimate interests for platform security, fraud prevention, measurement, and service improvement; and on legal obligation where retention or disclosure is required by law. Where we rely on legitimate interests, you may object at any time.
Partner data
Data a partner uploads or connects to the platform remains that partner's property. We process it only to deliver the services under that partner's Schedule, and we do not use one partner's data to provide services to another partner without prior written consent. Data clean room collaborations run on common identifiers only, without exposing underlying records to either side.
Sharing and international transfers
We share personal data with supply and demand partners transacting through the platform, with infrastructure and analytics providers acting on our instructions, and with regulators or law enforcement where legally required. As an advertising platform operating globally, data is transferred internationally. Where required, transfers are covered by an appropriate mechanism such as Standard Contractual Clauses.
Partners requiring a Data Processing Addendum should contact [email protected]. A DPA is entered into where required by applicable data protection regulation.
Retention
Bid and delivery data is retained only as long as needed for reporting, billing, fraud investigation, and model training, after which it is deleted or aggregated so that it no longer identifies an individual. Business contact data is retained for the duration of the relationship and for the period afterwards required to meet legal and accounting obligations.
Security
We maintain technical and organizational measures to protect data against unauthorized access, loss, and alteration. Where we confirm or reasonably suspect a data breach affecting partner data, we notify the affected party in writing within seventy-two (72) hours of becoming aware of it, with the nature and scope of the incident, the categories of data affected, and the mitigations taken or proposed. Further detail is on our Security page.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to processing, to portability, and to withdraw consent. Residents of California may exercise rights under the CCPA and CPRA, including the right to opt out of sale or sharing, through Your Privacy Choices.
We comply with applicable data protection regulations including the GDPR, CCPA, CPRA, LGPD, and PIPL. To exercise a right, contact [email protected]. We will not discriminate against you for exercising one. If you are in the EEA or UK and are not satisfied with our response, you may lodge a complaint with your supervisory authority.
Children
The platform is a business service and is not directed at children. We do not knowingly process the personal data of children, and we do not permit advertising to be targeted at them. If you believe a child's data has reached us, contact us and we will delete it.
Changes
We update this policy as the platform and the law change. Material changes are reflected in the version and effective date at the top of this page.